← back
CVE-2015-5688

CVE-2015-5688

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 9.4%
exploitation probability
9.4%top 5% of all CVEs
observed exploitation
nono source reports it
Directory traversal vulnerability in lib/app/index.js in Geddy before 13.0.8 for Node.js allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the PATH_INFO to the default URI.
Affected products
n/a · n/a